Menu
Browse

Cyber Incident Victim: MotorCycle Holdings

Date:

Apr 2024

Location:

Australia

Summary

A cyber attack compromised a third-party web server hosting MotorCycle Holdings' Sherco and Lambretta websites, enabling unauthorized access to customer data including names, addresses, email addresses, and phone numbers via malicious code injection. The threat actor also accessed stored customer responses submitted through web forms on these platforms. The company confirmed its internal systems remained secure and operational, with no broader compromise detected, and stated only affected customers would be directly notified. The breach was isolated to the third-party infrastructure supporting its MOJO Motorcycles subsidiary, and investigations are ongoing to establish further details.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

MotorCycle Holdings Limited (ASX: MTO), an Australian motorcycle distributor, disclosed a data breach impacting its MOJO Motorcycles business units Sherco and Lambretta on April 1, 2024. The company confirmed an unauthorized threat actor compromised a third-party vendor’s web server hosting these branded websites. The attacker inserted malicious code into the websites, potentially exposing customer personal information including names, addresses, email addresses, and phone numbers. Additionally, the actor accessed the server storing customer responses submitted through web forms on the Sherco and Lambretta sites. MotorCycle Holdings emphasized that its internal corporate network remained secure and isolated from the compromised third-party systems, confirming no broader compromise of company platforms. The breach exclusively affected the MOJO Motorcycles division, which MotorCycle Holdings acquired in October 2022.

Cyber Incident Image

The company initiated individual notifications to customers whose data was confirmed as exposed, clarifying that unaffected customers would not be contacted. MotorCycle Holdings stated the incident had no operational impact and assured stakeholders that its investigation remained ongoing. No details regarding the threat actor’s identity, motivations, or potential financial losses were disclosed. Updates were pledged to customers, shareholders, and stakeholders as the investigation progressed. The breach announcement was authorized by the company’s Disclosure Committee, with Managing Director David Ahmet and CFO Nicole Spink designated as contacts for further inquiries.

Sources
Sources available to members
2 sources